To associate with an innovative and vibrant organization, allowing me to put my competencies to the best use, to add value to the organization and contribute to my overall growth as an individual.
Professional Summary
SIEM Tools: Splunk Enterprise and Enterprise Security
Vulnerability Management: Nessus
Incident Analysis Tools: CISCO Talos, Mx Toolbox, Virus Total, IBM-Xforce etc.
Ticketing Tool: Service Now
● A competent professional with 2.5 Years of experience in IU technologies Pvt ltd as Security Analyst.
● Cyber Security Analyst with proficient and thorough experience and a good understanding of information technology. Specialized in proactive network monitoring of SIEM
● Good understanding of security solutions like Anti-virus, Firewall, IPS/IDS, Email Gateway, Proxy etc.
● Hands on experience with Splunk SIEM tool for logs monitoring and analysis, using Service Now ticketing tool for incidents response
● Good knowledge on networking concepts including OSI Model, Subnetting, TCP/IP, ports, DNS, DHCP etc.
● Working in a 24x7 Security Operations Center
● Monitoring security solutions and detect malicious network activity using Splunk SIEM
●Monitoring Real-Time logs, Investigation, Analysis report incident
● Analyzing Realtime security incidents and checking whether its true positive or false positive
● Performing Real-Time Monitoring, Investigation, Analysis, Reporting and Escalations of Security Events from Multiple log sources.
● Raising true positive incidents to the respective team for further action
● Creating tickets on service now and assigning it to the respective team and taking the follow-up until closer
●Monitoring security tools like Crowd strike.
●Investigate malicious phishing emails, domains, and IPs using open source tools
●recommend proper blocking based on analysis
● Good knowledge of Splunk Distributed cluster Architecture
● Detail knowledge of the working functionality of various components of Splunk such as Indexer, Search head, Heavy forwarder, deployment server etc.
● Experience in onboarding of data sources with Splunk such as Windows, Linux, Fortinet Firewall etc.
● Installing Splunk apps and Addon on the Splunk
● Experience in installation of Universal forwarder on the servers for logs collection
● Doing the troubleshooting in case any device is not reporting to the Splunk
● Knowledge of Creating dashboard, Reports in Splunk
● Knowledge and experience in creating Correlation Searches/Rules in Splunk
● Working experience searching and Reporting in Splunk having good SPL knowledge